Summary
CVE-2026-71485 is a critical authentication bypass vulnerability (CWE-290: Authentication Bypass by Spoofing) affecting Centrifugo, the open-source real-time messaging server, in versions prior to 6.9.0. The flaw allows a remote, unauthenticated client to forge trusted headers that Centrifugo forwards to backend proxy services, which can result in full identity or authorization spoofing. The issue carries a CVSS v3.1 base score of 9.1 (Critical).
Technical details
- Root cause: Centrifugo’s
http_headersandgrpc_metadataproxy options are meant to forward header/metadata values that originate from trusted transport-level HTTP requests, but the implementation instead copies values from the client-controlledprotocol.ConnectRequest.headersmap (received directly from the client) into an internal "emulated headers" context used by every proxy call. - Affected code paths include the header/metadata construction logic used for HTTP and gRPC proxy backends, as well as the unidirectional gRPC connection handler.
- Trigger condition: a backend must be configured to trust forwarded headers (e.g.,
x-trusted-user) for authentication or authorization decisions when using Centrifugo’s connect, refresh, subscribe, publish, or RPC proxy calls. - Attack vector: network, no authentication or user interaction required — an attacker simply connects to Centrifugo and supplies arbitrary header values in the client connect command.
- Impact: high confidentiality and integrity impact (attacker can impersonate trusted users/headers and gain unauthorized access to backend resources); no availability impact.
Affected software
- Centrifugo (Centrifugal), all versions prior to 6.9.0
Severity
- CVSS v3.1 Base Score: 9.1 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate: Upgrade Centrifugo to version 6.9.0 or later, which addresses the header-forwarding logic.
- If immediate patching is not possible: Do not rely on Centrifugo-forwarded
http_headersorgrpc_metadatavalues (e.g.,x-trusted-user) for authentication or authorization decisions on backend proxy services, since these values can originate from client-supplied data rather than genuine trusted transport headers. Review proxy backend configurations for any sensitive access-control logic keyed on forwarded headers and disable or restrict such trust until patched.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
Centrifugo

